Ask a small business owner what's exposed to the internet and most will point to the website. That's rarely the full picture. Between an old marketing subdomain still pointing at a decommissioned server, a VPN portal set up for a project that wrapped up two years ago, and a cloud storage login that belonged to someone who left the company last spring, the real answer is usually a list nobody has ever written down. Attack surface management is the practice of writing that list, from the outside, the same way an attacker would build it, and then actually doing something about what's on it.
Why your attack surface is bigger than you think
Nobody sets out to expose more than they mean to. It happens the same way clutter accumulates anywhere: one reasonable decision at a time, none of them tracked against the others. A developer spins up a quick staging site to show a client and forgets to take it down. A vendor gets temporary remote access for a project and the account never gets revoked. A DNS record for an old email marketing tool keeps pointing somewhere that hasn't been renewed in years. None of these felt risky when they happened. Stacked together, they're a set of doors nobody remembers unlocking.
- Forgotten subdomains and DNS records. Marketing campaigns, product demos, and old vendor integrations leave subdomains resolving long after anyone uses them, some pointing at infrastructure that's been retired and can be hijacked outright.
- Orphaned accounts and logins. Former employees, past contractors, and vendors whose engagement ended months ago often keep working access to cloud storage, email, or admin panels because offboarding covers the obvious systems and misses the rest.
- Shadow IT. Tools an employee signed up for with a company email, outside of anything IT approved or even knows about, each with its own login and its own exposure. Our shadow IT post covers how this creeps in.
- Exposed remote access. A VPN appliance, an RDP port left open for a one-time fix, or an admin panel that was supposed to be temporary, all reachable from anywhere, indefinitely, until someone checks.
- Cloud storage with the wrong sharing default. A folder shared "anyone with the link" for a single external review that never gets set back to private.
How small businesses actually find out what's exposed
The starting point is discovery from the outside looking in, not a walk-through of what IT thinks is running. Domain and subdomain enumeration maps every hostname tied to the business, including the ones nobody remembers registering. Port and service scanning shows what's actually reachable on the open internet right now, not what a diagram from two years ago says should be. Cloud account reviews catch former employees and vendors who still have working logins long after their reason for having one ended. And a breach-data check tells you whether credentials tied to company email addresses are already circulating from an unrelated third-party breach, which matters because reused passwords turn someone else's incident into yours; our dark web monitoring post goes deeper on that piece specifically.
This is a different exercise from a penetration test, and the two get confused often enough that it's worth being precise about it. A pentest asks "how far could an attacker get into the systems we already know about?" Attack surface management asks the question that comes first: "what do we actually have exposed, including the parts nobody remembers?" Skipping straight to a pentest without doing the discovery first means testing against an incomplete map, and the thing that gets you breached is rarely the system everyone was already watching.
Turning visibility into a shrinking attack surface
Finding the list is the easy half. The harder, more valuable half is deciding what to do with each item on it, and most of it is cleanup rather than new engineering. Anything genuinely unused gets decommissioned outright: the DNS record gets deleted, the server gets shut down, the account gets revoked. Anything still needed but overexposed gets restricted, an admin panel that has to exist doesn't have to be reachable from any IP address on earth; putting it behind a VPN or an allowlist removes it from the public attack surface without removing the functionality. Everything that remains gets MFA, current patches, and a place on the inventory so it doesn't quietly become "forgotten" again in six months.
The part that actually holds up over time is treating this as a cadence, not a project with an end date. New exposures appear constantly, a landing page for a seasonal promotion, a demo environment for evaluating new software, a contractor's temporary access, so a scan done once and filed away is stale within weeks. Continuous or monthly discovery, paired with the offboarding discipline covered in our employee offboarding post, is what keeps the list accurate instead of aspirational.
Where this fits
- The domain name security post, for the exposure most likely to get hijacked entirely, not just abused.
- The shadow IT post, for how unauthorized tools quietly add to what's exposed.
- The VPN and edge device flaws post, for what happens when an internet-facing appliance turns out to be vulnerable.
- The dark web monitoring post, for checking whether your exposure has already turned into stolen credentials.
- Our penetration testing and managed detection & response services, for testing what an attacker could do with what's exposed, and watching for it around the clock afterward.
We run attack surface discovery as part of security assessments for small businesses across Salinas, Monterey, Santa Cruz, Watsonville, and San Jose, and the rest of the Central Coast, so "here's what we're exposed to" is a real list, not a guess.
FAQs about attack surface management for small business
What is attack surface management?
Attack surface management (ASM) is the ongoing process of discovering, inventorying, and monitoring every asset a business exposes to the internet, domains, subdomains, cloud logins, VPN portals, servers, and APIs, from an outside attacker's point of view, so unknown or forgotten exposures get found and closed before someone else finds them first.
How is attack surface management different from a penetration test?
A penetration test is a point-in-time, hands-on attempt to break into systems you already know about, testing how deep an attacker could get. Attack surface management runs continuously and answers a different question first: what do we actually have exposed to the internet, including assets nobody remembered were still running. ASM finds the target list; a pentest tests how well it holds up.
How often should a small business scan its attack surface?
Attack surface discovery should run continuously or at minimum monthly, not once a year. New assets appear constantly, a marketing team spins up a landing page, a vendor demo leaves a subdomain live, a departing employee's cloud account never gets removed, and an annual review misses everything that showed up and disappeared in between.
Can a small business reduce its attack surface without hiring a security team?
Yes. Most of the reduction is decommissioning and cleanup work, not advanced engineering: retiring unused subdomains and DNS records, closing accounts for former employees and vendors, taking test and staging sites offline or off the public internet, and turning on MFA everywhere that remains. A managed IT provider can run the discovery and handle the cleanup on a schedule.
Not sure what your business actually looks like from the outside?
30 minutes with an engineer with DoD infrastructure experience. We'll map what's exposed, what's forgotten, and what closing the gaps actually costs, no scanner install, no obligation.
Book your free security assessment